A fake desktop application impersonating Anthropic’s Claude is reportedly being used as a delivery mechanism for RevStealer, a Windows malware family designed to harvest sensitive information from victims and then target a wide range of cryptocurrency wallets.
In a report published Monday, cybersecurity firm Morphisec says the campaign has evolved beyond earlier distribution methods that relied on GitHub repositories and game-cheat-themed sites, with one of the most prominent lures being a project dubbed “Claude Opus 5 Free Desktop.” The name suggests free access to Claude while disguising malware intended to steal crypto and broader account credentials.
Key takeaways
- Morophisec links the latest RevStealer infections to a fake “Claude Opus 5 Free Desktop” download that impersonates Anthropic/Claude.
- The malware focuses on stealth, including searches of browser data, cookies, password-manager records, VPN/remote-access settings, and selected files.
- RevStealer targets more than 50 cryptocurrency wallets and attempts to avoid analysis by checking for “real user” environments.
- Its staging includes environment and debugging-delay checks; if the system doesn’t meet the criteria, the malware halts further activity.
Fake Claude desktop lure points to continued social-engineering
According to Morphisec, RevStealer was previously pushed through channels such as GitHub repositories and websites themed around game cheating. While those delivery routes remain common for commodity malware, the firm highlights a more noticeable ruse: a counterfeit “Claude Opus 5 Free Desktop” project that mimics the branding of the AI developer Anthropic and presents the promise of free Claude access.
This matters for users because it reflects how crypto-targeting threats increasingly blend into everyday software expectations. Instead of asking victims to install a clearly suspicious file, attackers wrap their payloads in familiar UI assumptions—an “app” users might treat as legitimate productivity software.
What RevStealer looks for—and where it steals
Morphisec says RevStealer is built to minimize its forensic footprint while broadening the scope of harvested data. The malware searches browser databases and related artifacts such as cookies, password-manager records, and other stored session information.
The threat also goes beyond typical credential theft by collecting details connected to remote access and privacy tooling, including VPN and remote-access settings. It further targets messaging-related data and takes screenshots, alongside selected documents.
On the crypto side, Morphisec notes that RevStealer targets over 50 cryptocurrency wallets. For investors and everyday users, the key risk is that stolen wallet access can enable asset movement without needing the attacker to break the wallet software itself—if the victim’s wallet files or credentials are extracted, the next step can be direct unauthorized control.
Environment checks designed to frustrate researchers
A notable feature of the RevStealer infection chain, according to the Morphisec report, is a multi-part gating mechanism. Before unlocking the next stages, the malware checks whether the machine resembles a genuine user device.
The researchers describe checks based on available memory, processor core count, hostname and username characteristics, and graphics hardware. Morphisec also adds that RevStealer monitors for debugging delays that are typical in malware analysis environments.
If the malware detects anything it considers abnormal, it does not proceed further—meaning it can reduce the amount of observable behavior available to analysts and slow down detection efforts. When the checks pass, Morphisec reports that the payload is decrypted, saved under a random filename, and executed covertly.
For defenders, this implies that “it didn’t run” can be a deliberate outcome rather than a sign of a clean system. It also highlights why behavioral detection and endpoint monitoring still matter: relying solely on static indicators or single-run samples may miss threats that deliberately stall during investigation.
Broader trend: crypto-investor malware frameworks keep expanding
The RevStealer report lands amid other research targeting people involved with cryptocurrency investing. Earlier coverage referenced discovery by Kaspersky of a new malware framework called OkoBot, described as targeting crypto investors by harvesting wallet files, browser data, and user credentials.
As noted by Kaspersky in that separate discovery, OkoBot can also inject malicious extensions and capture wallet application windows to help steal assets. While the Morphisec write-up focuses specifically on RevStealer, both cases point to a persistent pattern: attackers are combining browser/session theft with wallet-targeted collection and increasingly using realistic lures.
For readers, the important takeaway is not just that malware exists, but that campaigns are diversifying their tooling and delivery methods while remaining aligned around a shared objective—access to crypto storage and the credentials needed to move money.
What users and teams should watch next
With scams now leveraging credible-sounding AI branding and malware that attempts to detect analysis environments, the immediate priority is operational hygiene: treat “free” desktop downloads—especially ones impersonating well-known companies—as high-risk, avoid installing unknown software from community-hosted pages, and verify integrity before execution. Meanwhile, security teams should expect more wallet-focused stealers that pair broad browser-data harvesting with stealthy, environment-aware execution.






